Re: [v6ops] new draft: draft-ietf-v6ops-6204bis
"Dan Wing" <dwing@cisco.com> Fri, 14 October 2011 22:04 UTC
Return-Path: <dwing@cisco.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14D2021F8C6E for <v6ops@ietfa.amsl.com>; Fri, 14 Oct 2011 15:04:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -105.099
X-Spam-Level:
X-Spam-Status: No, score=-105.099 tagged_above=-999 required=5 tests=[AWL=1.500, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KzedtuXhTn9R for <v6ops@ietfa.amsl.com>; Fri, 14 Oct 2011 15:04:24 -0700 (PDT)
Received: from mtv-iport-1.cisco.com (mtv-iport-1.cisco.com [173.36.130.12]) by ietfa.amsl.com (Postfix) with ESMTP id 465FC21F8C60 for <v6ops@ietf.org>; Fri, 14 Oct 2011 15:04:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=dwing@cisco.com; l=4127; q=dns/txt; s=iport; t=1318629864; x=1319839464; h=from:to:cc:references:in-reply-to:subject:date: message-id:mime-version:content-transfer-encoding; bh=IH/KjiImaN3XIWSJnUU0gUlTEaweKlOHIYThspHo0Ng=; b=mGRghm7q2/OmWH0MXt9gs6hrT/Q0ZZFx4cBJkLKdtO5yIOr5HATWWtRe iRUlFA6rer81NClhO3fnim8pLwHPnGlAawgGqpA7iaUQDAG3iaEjMCdOE cG5J6PwTbb86RYUnapqOvoVyII4iZxKjmV9gQs7yu5fc8PySgVA9RnnLS g=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: ApMAAISxmE6rRDoG/2dsb2JhbABDhHaUSYFsjAaBNoEFgW4BAQEBAgEICgEQBz0SBQcBAwIJDgECBAEBAwIjAwICGSMKCQgBAQQTCxeHXZkwAYxHkXuBLIU5gRQEiAGdaw
X-IronPort-AV: E=Sophos;i="4.69,348,1315180800"; d="scan'208";a="7957745"
Received: from mtv-core-1.cisco.com ([171.68.58.6]) by mtv-iport-1.cisco.com with ESMTP; 14 Oct 2011 22:04:21 +0000
Received: from dwingWS (dhcp-128-107-145-2.cisco.com [128.107.145.2]) by mtv-core-1.cisco.com (8.14.3/8.14.3) with ESMTP id p9EM4LpJ018554; Fri, 14 Oct 2011 22:04:21 GMT
From: Dan Wing <dwing@cisco.com>
To: 'Tassos Chatzithomaoglou' <achatz@forthnetgroup.gr>
References: <4E974F1A.2030008@forthnetgroup.gr> <033d01cc8a0f$df61c190$9e2544b0$@com> <4E97E806.6090209@forthnetgroup.gr>
In-Reply-To: <4E97E806.6090209@forthnetgroup.gr>
Date: Fri, 14 Oct 2011 15:04:21 -0700
Message-ID: <06e701cc8abd$3a146950$ae3d3bf0$@com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcyKRO8OYZYehRVfSb+K26oO3CFnnQAZX0Cw
Content-Language: en-us
Cc: v6ops@ietf.org, draft-ietf-v6ops-6204bis@tools.ietf.org
Subject: Re: [v6ops] new draft: draft-ietf-v6ops-6204bis
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 14 Oct 2011 22:04:25 -0000
> -----Original Message----- > From: Tassos Chatzithomaoglou [mailto:achatz@forthnetgroup.gr] > Sent: Friday, October 14, 2011 12:43 AM > To: Dan Wing > Cc: v6ops@ietf.org; draft-ietf-v6ops-6204bis@tools.ietf.org > Subject: Re: [v6ops] new draft: draft-ietf-v6ops-6204bis > > > Dan Wing wrote on 14/10/2011 04:23: > >> -----Original Message----- > >> From: v6ops-bounces@ietf.org [mailto:v6ops-bounces@ietf.org] On > Behalf > >> Of Tassos Chatzithomaoglou > >> Sent: Thursday, October 13, 2011 1:51 PM > >> To: v6ops@ietf.org; draft-ietf-v6ops-6204bis@tools.ietf.org > >> Subject: [v6ops] new draft: draft-ietf-v6ops-6204bis > >> > >> > >> Just to add to everyone else that expressed the desire to see DS- > Lite > >> in this, i totally agree with them. > >> We recently run an RFP looking for IPv6 CPEs from various vendors > and > >> nobody of them had a official version supporting it. > >> We even got answers from vendors (that are very active inside IETF), > >> that they are not planning to implement it. > >> So having a standard RFC "pushing" them in that direction is always > >> welcome. > >> > >> Regarding PCP, i would also like to have it as a basic requirement. > But > >> i can live with the assurance that when finished, it will be added > >> (maybe somewhere else). > >> Currently, we are planning to enable DS-Lite only to subscribers > that > >> have all port forwarding methods disabled in their CPE, so we can > >> "bypass" a need for it. > >> But as the number of subscribers grows, we'll surely need a way to > make > >> port forwarding (+other stuff) work in CGN. > > PCP is not just about IPv4 and is not just about CGN. > > > > Ignore IPv4 for a moment. Let's concentrate on IPv6. > > > > For IPv6, if the CPE going to comply with RFC6092 (Simple CPE > > Security), incoming unsolicited traffic will be blocked. If the > > IPv6 host is hoping to run an Internet-facing server, the host and > > and CPE will need to either: > > (1) implement UPnP IGD 2.0 (which supports IPv6 firewall), or > > (2) implement PCP (which supports IPv6 firewall), or > > (3) the user will have to configure exceptions manually in > > their CPE (e.g., using web pages). > > > > I think PCP is the best answer of those three, because it works > > in all anticipated mixes of technology that may be deployed on > > a particular network for that network's IPv6 transition, > > including NAT64, NPTv6, NAT46, NAT44, etc. > > > > -d > > Dan, > > I had the impression that for Internet-facing servers the best (in > terms of 100% correct > behavior) answer was No 3; configure it manually on the CPE. > At least this is based on my experience on IPv4 CPEs (haven't seen a > fully working firewall on IPv6 CPEs). > On other hand, i am more of a manual config guy (i want to know what's > open and what's > not), so maybe i am missing the typical subscriber's "best" answer. The typical subscriber doesn't have any clue how to configure their CPE, nor understand the need to do so. Think of Joe Sixpack, Grandma, or the actors on TV commercials as typical subscribers -- not IETFers who are smart enough to be involved in IPv6. > Imho seeing PCP client support in hosts and applications might take a > while. I was hoping > for PCP on the CPE WAN side as a first. I see it as more urgent. It's all in what Apple/Linux/Microsoft add to their products. > btw, quoting from draft-ietf-pcp-base-14, "Introdution": > > PCP is designed to be implemented in the context > of both Carrier-Grade NATs (CGNs) and small NATs (e.g., residential > NATs). PCP allows hosts to operate servers for a long time (e.g., > a > webcam) or a short time (e.g., while playing a game or on a phone > call) when behind a NAT device, including when behind a CGN > operated > by their Internet service provider. > > Although, IPv4/IPv6 firewalls are referenced further inside the text, i > would like to see > them here too. Ok, will be mentioned in -15 up front. Thanks. -d > > > -- > Tassos
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- [v6ops] new draft: draft-ietf-v6ops-6204bis fred
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis STARK, BARBARA H
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis STARK, BARBARA H
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Simon Perreault
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis STARK, BARBARA H
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ole Troan
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis christian.jacquenet
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Simon Perreault
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis François-Xavier Le Bail
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Stuart Cheshire
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis christian.jacquenet
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Stuart Cheshire
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti
- [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Doug Barton
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Fred Baker
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ole Troan
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Weil, Jason
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis STARK, BARBARA H
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Victor Kuarsingh
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ole Troan
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tassos Chatzithomaoglou
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Maglione Roberta
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Wes Beebee
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis STARK, BARBARA H
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Wes Beebee
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Alain Durand
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Reinaldo Penno
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis christian.jacquenet
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ole Troan
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Tina TSOU
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Reinaldo Penno
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis mohamed.boucadair
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Jeroen Massar
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Jared Mauch
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Jeroen Massar
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Dan Wing
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Jared Mauch
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Mark Andrews
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis james woodyatt
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ray Hunter
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Washam Fan
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Hemant Singh (shemant)
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis SM
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Ray Hunter
- Re: [v6ops] new draft: draft-ietf-v6ops-6204bis Lorenzo Colitti